[lockfile-stats] Lockfile Statistics Analysis — 2026-09-25 #63508
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Lockfile Statistics Analysis Agent. A newer discussion is available at Discussion #63672. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Lockfile Statistics — 2026-09-25
Analysis of all
.github/workflows/*.lock.ymlcompiled workflow files ingithub/gh-aw. Methodology: single-script compact JSON analysis (lockfile_stats_v4.py, cached incache-memory/scripts/).Executive summary
workflow_dispatchenabledcreate_discussionconfiguredFile size distribution
Sizes cluster tightly around the mean (~153 KB), with a ~2.7x spread between smallest and largest lockfile — largest files correlate with high job/step counts (see Structural characteristics).
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(209, 70.1%),workflow_dispatchalone (37),pull_request+schedule+workflow_dispatch(29),pull_request+workflow_dispatch(9).Cron concentration: 42 workflows (17.4% of the 242 scheduled) share the exact same cron
0 0 */2 * *(every 2 days at midnight UTC) — the single largest cluster by far. The remaining ~200 scheduled workflows are scattered across unique minute/hour offsets (mostly count 1-3), suggesting deliberate staggering elsewhere but a stampede risk at that one slot.Safe outputs analysis
Built-in safe-output primitives (
missing_data,missing_tool,noop,report_incomplete,create_report_incomplete_issue) appear in 292/298 (98.0%) of workflows — effectively universal infrastructure.Full safe-output type tail (54 types total)
upload_artifact 14, create_check_run 14, push_to_pull_request_branch 11, update_issue 10, max_bot_mentions 8, close_issue 7, remove_labels 7, comment_memory 6, dispatch_workflow 6, update_pull_request 5, assign_to_agent 5, link_sub_issue 4, close_pull_request 4, send-slack-message 4, create_code_scanning_alert 3, close_discussion 3, reply_to_pull_request_review_comment 3, set_issue_type 3, and 20+ types at count 1-2 (jira_*, linear_create_issue, update_project, etc.)
Discussion categories (92
create_discussionworkflows, 100% category-resolved, 0 unresolved):Self-check passed:
create_discussion_workflows(92) ==discussion_category_detected(92);safe_outputs_config_missing= 0.Structural characteristics
Permission patterns
Derived from
jobs.<name>.permissions(the top-levelpermissions: {}carries no signal).Agent job (matches workflow frontmatter) — overwhelmingly read/none, confirming the agent itself runs least-privilege:
Union across all jobs in a workflow (includes the safe-outputs apply job) — 298/298 (100%) grant some write scope:
Engine distribution
From
gh-aw-metadataagent_id(0 unknown across 298 lockfiles):Top resolved models:
openai/gpt-5.3-codex(37),copilot/gpt-5.3-codex(33),copilot/auto(30),openai/gpt-5.4(11),claude-sonnet-5(6). One workflow resolves its model dynamically at runtime (${{ needs.activation.outputs.model_size }}), invisible to static analysis.Tool & MCP patterns
Long tail (1-2 workflows each): ast-grep, datadog, deepwiki, microsoftdocs, grafana, kreuzberg, mempalace, graft, agentdb, ruflo. All 298 lockfiles resolved via manifest parsing — 0 required the legacy comment-scraping fallback.
Interesting findings
issues(39 even havenone), yet the union across all jobs grantsissues: writein 100% of workflows — even though only 48.7% configurecreate_issueand 25.5% configureadd_comment. The safe-outputs apply job appears to request a fixed permission set regardless of which output types are actually enabled.0 0 */2 * *slot, dwarfing every other cron cluster (next-largest is 3).create_discussionworkflows targetaudits(like this report); the other 6 categories split the remaining 13 workflows thinly.create_discussion_workflows, and the full engine distribution are all unchanged; total bytes drifted by only +3,241 (+0.007%) — a quiet 24 hours for workflow authoring.Historical trends
Compared against prior snapshot
2026-09-24.json(20 days of history available, 2026-08-30 → 2026-09-25):Recommendations
issues: writeunconditionally, or could scope permissions to only the output types a given workflow configures (least privilege).0 0 */2 * *cron to reduce simultaneous-run contention.auditsnow accounts for 86% of discussion output — consider whether report subtypes warrant their own categories as volume grows.Methodology: single-script compact JSON analysis.
All reactions